11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

780 <strong>Improving</strong> <strong>Web</strong> <strong>Application</strong> <strong>Security</strong>: <strong>Threats</strong> <strong>and</strong> Countermeasures Create IP filters <strong>and</strong> filter lists1. Right-click IPSec <strong>Security</strong> Policies on Local Machine, <strong>and</strong> then click Manage IPfilter lists <strong>and</strong> filter actions.2. Click Add to add a new IP filter list., <strong>and</strong> then type MatchAllTraffic for the filterlist name.3. Click Add to create a new filter <strong>and</strong> proceed through the IP Filter Wizard dialogsboxes by selecting the default options.This creates a filter that matches all traffic.4. Click Close to close the IP Filter List dialog box.5. Click Add to create a new IP filter list, <strong>and</strong> then type MatchHTTPAndHTTPS forthe filter list name.6. Click Add, <strong>and</strong> then click Next to move past the introductory Wizard dialog box.7. Select Any IP Address from the Source address drop-down list, <strong>and</strong> thenclick Next.8. Select My IP Address from the Destination address drop-down list, <strong>and</strong> thenclick Next.9. Select TCP from the Select a protocol type drop-down list, <strong>and</strong> then click Next.10. Select To this port <strong>and</strong> then specify port 80.11. Click Next <strong>and</strong> then Finish.12. Click Add, <strong>and</strong> then repeat steps 9 to 14 to create another filter that allows trafficthrough port 443.Use the following values to create a filter that allows TCP over port 443:●●●●Source Address: Any IP addressDestination Address: My IP AddressProtocol: TCPFrom Port: Any● To Port: 443After finishing these steps, your IP Filter List should look like the one that Figure 5shows.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!